earliest=-1h: Searches for events in the last 1 hour.
For example, on the screenshot, I set two hosts to monitor and earliest -1s for testing. Now, if they stop coming, you will see results like on the screenshot.
Step 2: Create an Alert
In Splunk:
Go to Settings > Searches, reports, and alerts.
Click New Alert.
Configure the New Alert:
Title the alert (e.g., Multiple Source Monitor).
Description (Optional)
Search (your write query in step 1)
Set the alert to run on a schedule (e.g., every 5 minutes or hourly).
Trigger when the number of results (sources with zero logs) is greater than 0.
Set action when triggered (For example, webhook)
Save alert
Finally, you will see your alert, and when it’s triggered, you will see it For example, on the screenshot, I set sending to http port
Join SOC Prime's Detection as Code platform
to improve visibility into threats most relevant to your business. To help you get started and drive immediate value, book a meeting now with SOC Prime experts.